Check your download
Make sure the file is complete and really comes from VelaOS before you write it to a USB stick.
Two checks, a few minutes in total. The signature proves that the list of checksums was made by VelaOS. The checksum proves that your file matches that list, byte for byte. If either check fails, don't use the file: delete it and download it again.
What you need
- From Downloads (log in first): the image file, for example
velaos-26.10-amd64.raw.zst, plusSHA256SUMSandSHA256SUMS.sig. - The VelaOS public key,
velaos.pub. It is printed below and on the Downloads page. - Put all four files in the same folder, and open a terminal in that folder.
The VelaOS public key
This key is public, so it is safe to share. Save it as velaos.pub. It is the same key every VelaOS device uses to check its updates.
1. Check the signature
- 1
Install cosign
cosign is a free signing tool from the open-source Sigstore project. Get it from the cosign install page:
- macOS:
brew install cosign - Linux: your distribution's package (
dnf install cosign,apt install cosign) or the release binary - Windows: download
cosign-windows-amd64.exefrom the cosign releases page and rename it tocosign.exe
- macOS:
- 2
Check the checksum list against the VelaOS key
The same command works in Terminal (macOS, Linux) and PowerShell (Windows):
cosign verify-blob --key velaos.pub --signature SHA256SUMS.sig --insecure-ignore-tlog=true SHA256SUMSIt must end with
Verified OK. Anything else means the list was changed or isn't from VelaOS: stop here.Why --insecure-ignore-tlog=true?
cosign warns that it skips the public Sigstore log. VelaOS releases are private, so they are not written to that public log. Your proof is the VelaOS key above, which is checked in full.
2. Check the SHA-256 checksum
Pick your computer. Each way ends with a clear yes or no.
Windows: PowerShell
- 1
Compare the file with SHA256SUMS
Open PowerShell in the download folder and paste:
$file = Get-Item .\velaos-*.raw.zst $expected = (Select-String -Path .\SHA256SUMS -Pattern $file.Name -SimpleMatch).Line.Split(' ')[0] $actual = (Get-FileHash $file -Algorithm SHA256).Hash.ToLower() if ($actual -eq $expected) { "OK: the checksum matches" } else { "STOP: the checksum does not match" }A large file takes up to a minute. You want
OK: the checksum matches.
Windows: Command Prompt
- 1
Print the checksum
certutil -hashfile velaos-26.10-amd64.raw.zst SHA256 - 2
Compare it by eye
Compare the 64 characters it prints with the line for your file in
SHA256SUMS, or with the SHA-256 on the Downloads page (use its copy button). Upper or lower case doesn't matter; every character must match.
macOS: Terminal
- 1
Check the file against SHA256SUMS
shasum -a 256 -c SHA256SUMS 2>/dev/null | grep velaosYou want
velaos-26.10-amd64.raw.zst: OK.FAILEDmeans the file is damaged or changed.
Linux: terminal
- 1
Check the file against SHA256SUMS
sha256sum --ignore-missing -c SHA256SUMSYou want
velaos-26.10-amd64.raw.zst: OK.FAILEDmeans the file is damaged or changed.
Both checks passed?
The file is complete and comes from VelaOS. Next: write it to a USB stick and install.
If a check fails
- Download the file again from Downloads. A broken connection is the usual cause.
- Make sure
SHA256SUMS,SHA256SUMS.sigand the image come from the same release (same version number). - Still failing? Don't install it. Tell us at velaos.ch/security: a file that fails its signature check can mean someone tampered with it.